Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementSecurity & Business ResilienceSecurity Education & Training

Staying Ahead of the Ransomware Industry

By Jordyn Alger, Managing Editor
5 minutes with Lance
Bio image courtesy of Lance
September 25, 2026

Mark Lance, SVP of Digital Forensics and Incident Response (DFIR) and Threat Intelligence at GuidePoint Security, shares with Security magazine how ransomware is evolving — and how organizations can stay ahead. 

Security magazine: Tell us about your background and experience in the security industry. 

Lance: I’ve been in cybersecurity for nearly 27 years, with roughly the last 17 focused specifically on incident response. I first got into IT almost by accident, having built my first computer to play video games in college. While I was studying for my Microsoft certifications, a friend’s parent wanted to develop a security professional rather than hire one and gave me a shot at a managed security services startup. I came up through the analyst ranks, moving from analyst to senior, principal, and eventually to the first lead analyst the company ever had, because I’ve always had an inquisitive, puzzle-solving mindset that pulled me toward the investigative side of the work. From there I moved fully into incident response, eventually building out global IR functions at multiple companies, and over the years I’ve helped organizations respond to everything from business email compromise to ransomware to nation-state and APT activity. Today, as SVP of DFIR and Threat Intelligence at GuidePoint Security, that investigative instinct and technical background still drives how I approach the work.

Security: How have you seen ransomware evolve?

Lance: Ransomware started out very opportunistic, taking a shotgun approach aimed at individuals, locking their systems and demanding a ransom to get access back. Threat actors quickly realized organizations had deeper pockets and more to protect, so they shifted from individuals to companies, and then from broad targeting to deliberately going after specific organizations where operational impact would increase the odds of getting paid. As defenders matured and adopted backups, the actors adapted again by moving laterally, establishing persistence, and specifically targeting backups to take recovery off the table. When organizations responded with immutable and segmented backups, the actors pivoted to stealing data and threatening to publish it, which is how we arrived at the double-extortion model, and now even exfiltration-only extortion with no encryption at all. The through-line is that every time defenders raise the bar, the ransomware ecosystem evolves to protect its ability to monetize.

Security: What are the most effective entry points for malicious actors? 

Lance: Despite all the new and novel techniques out there, the most effective initial entry points are still the old, foundational ones. We consistently see attackers get in through bad cyber hygiene, whether that’s unpatched systems, shadow IT, or exposed and vulnerable perimeter devices, along with successful phishing, lack of MFA, and more. The exploit or vulnerability may change, but the underlying methods to gain that first foothold have stayed remarkably consistent. Where we actually see the new and novel tradecraft is after they’re already inside, when they leverage that access to move laterally, tunnel, and exfiltrate data. In other words, they don’t need to reinvent how they get in when the basics keep working.

Security: How can organizations stay ahead of the ransomware industry?

Lance: It really comes down to awareness and education, and turning that into enablement. Every organization should have an incident response plan, and while it doesn’t need to be an exhaustive, task-by-task document, it should answer the key questions before an incident hits, such as who our third parties are, whether we have external counsel and cyber insurance, whether we have an IR service provider on call, how we determine severity, and who makes the critical decisions. That plan should be paired with playbooks tailored to the threats most relevant to your environment, because ransomware can impact any organization of any size across any vertical, from small businesses to the Fortune 100s. On top of that, the foundational controls still matter enormously, including MFA, EDR and appropriate visibility, network segmentation, and privileged access management. Staying ahead is really about combining those fundamentals with realistic threat modeling for what’s actually most likely to impact your organization.

Security: Anything else you would like to add?

Lance: The one thing I’d emphasize is enablement, awareness and information sharing. One of the biggest shifts I’ve seen over 27 years is the stigma around having an incident, because historically there was this idea that you didn’t talk about a breach since you should be ashamed of it. But in today’s threat landscape, where attacks are inevitable, this is something everyone is dealing with and there’s real value in sharing our experiences so others can learn from them and avoid the same fate. Even among competitors, I’m a strong proponent of getting together and sharing, not trade secrets or intellectual property, but the tactics and lessons learned, because we’re all facing the same adversaries. We’re far more effective against them when we work as a community than when we go it alone.

KEYWORDS: 5 minutes with organizational resilience ransomware threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Healthcare supplies

3 Healthcare Breaches in Quick Succession Raises Concerns

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man driving

150M Driver’s Licenses Exposed, Security Experts Discuss

Police lights

Family of Fatally Shot Security Guard Seeking Answers

Stressed woman

Ransomware Doesn’t Just Break Systems. It Breaks People.


AlertMedia sponsored webinar

Events

September 30, 2026

When ICE Visits Your Hospital

LIVE: September 30, 2026 at 2 PM EDT This webinar will discuss practical frameworks for developing policies, training staff, and coordinating with legal, compliance, and executive leadership before an enforcement action occurs.

October 7, 2026

Modernizing Travel Risk Management: How Security Teams are Strengthening Duty of Care

LIVE: October 7, 2026 at 2 PM EDT Learn how security teams have strengthened travel risk management for a global workforce. Move beyond manual monitoring to earlier, verified awareness and a more defensible approach to security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Rendered Microsoft icon

    Staying Ahead of the Cyber Curve: Strategic Security in a Shifting Landscape

    See More
  • Staying Ahead of the ATM Thieves – Maybe – as Shimming Gets More Sophisticated

    See More
  • travel security, travel safety, business travel

    Strategic safety planning: Staying ahead of business travel threats

    See More

Related Products

See More Products
  • Security of Information and Communication Networks

  • Physical Security and Safety: A Field Guide for the Practitioner

  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing